44. Data is Making the Enterprise Network Better – Tech Field Day Podcast
The amount of data that has been unearthed in the network over the past few years is astounding. We now have access to more information that we could ever hope to want about the status of packets transiting through the enterprise. But is this data causing networks to be more complex? In this episode of the Tech Field Day podcast, Tom Hollingsworth is joined by Pieter-Jan Nefkens, Matyas Prokop, and Dominik Pickhardt as they explore the rise in data-centric network design. They discuss the drivers behind the need for more focused deployments and how access to this amount of data is creating challenges for operations teams. They also look at how security plays a role in the amount of information gathered and what happens to it after it is collected.
Transcript
The world of enterprise. It seems to be overwhelmed with data that's always been bubbling under the surface, but now we've taken off the lid and we get access to it. In this episode of the Tech Field Day podcast, data is making the Enterprise Network better.
Welcome to the Tech Field Day podcast, where each episode to bring together a group of IT experts across a variety of enterprise technology fields to discuss a key idea or concept in the enterprise IT space. This podcast features a variety of perspectives of members of the Tech Field Day delegate community, and is often recorded in association with one of our events. Tech Field Day is a part of the Futurum group, and this podcast is also published on our sister company's site Techstrong tv.
We're gonna be at Cisco Live Amaya in Amsterdam, and we are very happy that you're tuning in to join us for our Tech Field day event. I'd take a moment for our guest to introduce themselves before we jump into the premise for today's topic, starting with Mattias. Hi Tom.
Uh, thank you for having me. So, um, I'm Mattias Proco. I'm the technology director in Nasic, uh, looking after data center and cloud practice.
Um, so as you can hear, um, I think my focus is primarily around the data center data and a cloud. Hello, my name is Peter o Nfn. net or on bluesky with PJ NF.
Yeah, I'm Dominic Picard, uh, at Network Alban and yeah, driving down the InfoSec and security world for quite a long time and yeah, happy to be here on the podcast. Alright, well thank you all very much for joining us. As always.
My name is Tom Hollingsworth, I'm an event lead and practice lead here at Tech Field Day in the Futureum Group. Let's jump into the premise for this episode. We have unearthed a lot of data in the past several years that has been hiding in our network and our security systems for a very long time.
And we've exposed this to all kinds of platforms that allow us to see what's really been going on and whether you're using machine learning or AI to surface those events. It has created this interesting conundrum where the more data that we unearth, the more complex things seem to be, which has caused some situations where it feels like network innovation has stalled and we may actually be worse off than we were before. The premise for this episode is actually a question, does data make networking better?
And I I want to kind of throw this out to the, the panel because obviously with this being related to Cisco Live, I think one of the biggest things we have to talk about is it's been about a year since the acquisition of Splunk by Cisco, and there's some questions about whether or not that is actually improving Cisco's networking products. Uh, has there actually even been any crossover in that area and is this better for operations teams or does it feel like you guys are just being swamped by the amount of knobs and buttons that are now available to press because suddenly we can see what's going on with them? Yeah, I I would, I would jump right into it.
I think often it is a problem. We are collecting the same data multiple times across multiple platforms. Yeah, you can have the same information in a, in a, let's say NetFlow analyzer, the NDR product and then also in Splunk.
And then also you can capture the traffic and what is kind of offer amazing me you open a support, take ticket with a, with a tech and show them the same information they're asking about and they say, no, we don't trust this. We would like that you start the P cap and download wire shack to, to show me the same data again. So it's kind of often how much do we also trust these data?
Is this really comprehensive all the time and is it really recorded in a easy to access, uh, fashion? Yeah, I think from my, from my perspective, it's also like when do you use the data, right? You know, what Dominic was saying is very much to link to using the data after something goes wrong.
Um, I think we're like now moving to the age of where if you have the right data and you are using the data, you can actually predict things, you know, before they go wrong. And I think that's, that's what's becoming quite interesting and probably even more challenging to Dominic's point. So if you have your data distributed, like how well you can actually predict that something bad will happen.
Um, so that's, that's what I'm seeing in, um, in with loads of our clients where the data are just so much like spread and distributed across like different silos. So it's not really fault of like having it too much data. I think the, the issue is very often that they have the right amount of data, but they're just too spread.
Uh, they're just too distributed and it's really hard to make some sense out of the data. Um, I don't know. Um, what I'm hearing is it's spread and yet it isn't depending on how, how your platform is running.
I mean, if you're running an a CI platform, everything is consolidated to apic. Uh, but to Dominic's point, yes, more data, but it's, I think also the use case. Um, I remember a Cisco live session ages ago where somebody told me, you can get information from SP traps another information protocol for management, but uh, get six k one of these old beasts still reliable.
Um, they, I think they had something like 200, 300 SP traps in total, but the slog messages were like a thousands and you can use those slog messages to allow the network to tell you that something is going so Wrong. So it's not only data, but it's how can you make data into information. I think that's actually more important and probably also one of the first steps to digitalization and machine even being able to do something with machine learning.
That's a good point, Peter on, and this is one of the things that I think that people need to kind of understand this information, this data, so, sorry, let me classify that properly. This data has always been there like, like the syslog has existed since the beginning of time. We just haven't been capturing it.
Or if we have, we've been sending it to a Syslog recorder and hoping that we could mung that data at some point. I mean, even using the term mung to extract useful information from the, the pile of data kind of entered the, the, the common lexicon of that stuff. What's changed recently is the way that we extract that data.
So for example, if you think back to some of the earliest implementations of machine learning algorithms, it was to extract data points, right? Um, we want to figure out, you know, are all of these, uh, login events related to each other? Or is the login followed by the user trying to escalate privilege in laterally move?
Is that an event in and of itself? Now, we have also gained capabilities to where machine learning is now more ai, call it what it is. I still think that it's partially machine learning under the hood, uh, but people are taking even more amounts of data in and forcing it through these functions that kick out.
Um, simple answers I guess would be the best way to put it. But we still really don't have a, a good idea of how it arrived at that decision. And that's one of the things that people have complained about modern ai, ai algorithms for quite a while, is I, I get that you gave me this answer, but I don't see how you got there and without me understanding how you got there, how can I have any faith in the answer that you've given me based on the inputs that I've shown you?
Yeah, and to, to the point from Peter and for also from Mathias, I think we are pretty good in collecting all these data and formatting them that we can search and university that is kind of a, a soft problem, but the prediction part and making out sense of complex problems there, I saw for simple things, we have good correlations, we have nice outputs, that's easy to do. But if we have, let's say six or seven dependent parameters, it, it is becoming, even with all these AI magic difficult to, uh, make out, uh, meaningful, uh, data. Yeah, I don't know.
Mathias, have you seen predictions that have been failed? So where you said, oh, next month you will be there and at the end of the day no, didn't work out that fashion. Yeah, many, many multiple.
And and I think like, you know, I, I was thinking to what you were saying, and Tom was saying, you know, I I think didn't we like, you know, collect the loads of data in, let's say, uh, in a, like a firewall space? You know, I think like in a, in a security, we're seeing where the teams are receiving so much telemetry about stuff and you are actually getting into the point where you're seeing loads of false alarms. And I think that's, that's, maybe that's the clear indicator that we just have a too much of a data.
You know, maybe there, there is the overload and even if we have more data, there will be just like more false alarms. So I'm quite hopeful for the ai ML will be able to sort of clear that noise and we can receive maybe even more data. I think it's gonna be necessarily like, you know, that, that it's just for 100% we will be receiving more and more data.
Like that's, that's a fact. Like, you know, there's not gonna be less data. We will be receiving more and more data.
So now it's probably about what intelligence you can build on top of these data and how you can correlate the data. So you're absolutely spot on Dominic, like, you know, like making some correlations and some like, you know, predictions based on like, you know, six different type of sources of the data. Uh, that's still very complicated and still very complex.
I don't think we're at the point where technology can correlate so many different sources and data together to give you some like, you know, clear like indication what is going on. But I think we're getting closer and closer. Uh, I've seen some, you know, good use cases of, to Tom's point, like, you know, using the, the basic LLMs for like, you know, searching for the patterns in the logs, you know, you can use the LMS these days for that.
Uh, and it's, and it's, it's, it's, it's pretty, it's pretty usable, but when it comes to combining it with the prediction, that's when you need to use like a different techniques and different approaches how to crunch that number. And that's when it's becoming a little bit, a little bit more complicated. Um, so I, I think like, you know, it, it's like when, when we, when I, I was discussing just today with one of our clients, it was about the tools which you are building on top of the data.
And I think, you know, their problem wasn't necessarily, we have too much data. The problem was with the tooling on top of the data, how to use those tools to present that data. Like is there like one single product, one single tool to use the data and show you everything you need to, there is not, like, you know, when you look at the observability, when you look at the monitoring, there's just like so many different tools which are good in something but maybe not so good in other things.
So you need to like, you know, leverage multiple different products on top of the same data. So I think that's, that's, you know, more of a pain point for lots of the enterprises these days. It's probably the layer on top of the, on top of data, uh, and what tools to use on top of the data.
Yeah. And, and there are some use cases where you just have nice correlation searches, they have a meaningful output, you can run it again, and this gives you nice things. But I think even in 10 years ahead, uh, uh, my voters, there will be analysts for complicated cases in the security space where you really have to dig into the data where months later you find out there was some attack on your system, a vulnerability that was not known, and then you have to really dig into the data into streams that you weren't aware before that this is maybe important.
Yeah, I give you a a good example, the solar wines case where more or less everybody was searching seven months after it happened in their data to find out what, uh, if they were affected by this one. And I think this will be continue. You can solve some problems with intelligent AI searches in some cases.
I just, you need some skilled people to to dig that out. Yeah. And, and like I said, like it will only get worse.
Like I'm, I'm, I'm quite excited that Cisco lives, so there will be these big announcements about the hyper fabric and like there will be like, you know, these like expansion into what Cisco will be doing in a data center space and you know, there has been some information about the DPU they will be using in the switches, which will literally create like firewall on each of the ports in your data center. That's gonna be loads of metrics, that's gonna be loads of data and loads of insight into single port. So I, I, you know, you can almost imagine that like one switch will have like 48 like single firewalls and then it's gonna be sort of like, you know, flooding all the data somewhere.
So we will be receiving even more data and it's gonna be interesting how Cisco will build again, that layer on top of the data how to like dive in into the data and how they're gonna work with that data. Does that really improve the operations of your network? I think 48 individual firewalls streaming out loads of data.
Uh, I mean I've done a couple of, of, I've supported a couple of a CI implementations both network centric and now in the middle of a big one with application centric. And usually most companies don't know how their applications are designed. So you're getting so many, um, false positives, uh, in your policies and that still takes a human, I think, to really analyze what is really normal behavior on your network and what is not.
And that's a very important point because a lot of the learned behaviors that we see require some kind of frame of reference for the algorithm to be able to sort things out. You know, you guys referenced the SolarWinds hack, um, you know, there are a lot of zero day exploits that are out there that we don't know what they're capable of doing because we've never seen this kind of exploit before. I mean, yes, once it happens, we kind of see similar kind of behaviors, right?
Like lateral movement, privilege escalation and those kinds of things, which sometimes these systems can see evidence of that in the data and pick up on it. But is it enough for us to be able to collect this data and leave it sitting around in the hopes that three months from now when the exploit is now known, we can go back and do a postmortem and go, oh yeah, that's what it is. Or should we hope for the ability to train these algorithms better with the data that we've got so that they can identify something and going, I don't know what's going on here, but I know what it looks like over here and this means there's a problem right here that you need to fix.
Yeah, I mean, like, so I'm not a security guy. Like, you know, I, I, I'm, I'm not, I'm not the expert, but like, you know, my understanding always about these bad actors is that they are always step ahead, uh, with you in terms of like, you know, like understanding what patterns and how they are trying to break into your data and your network. So I, I don't know if we will ever be in the point where, uh, anything around the AI ML will be able to tell us like, you know, like something is about to gonna happen.
I I think it will be able to tell you like, you know, probably approximately the last few hours or the last few days, yeah, I've seen something suspicious and then like raise some alarms and some alerts. But will we, we be able to say like, you know, something is about to happen. I, I don't know, I'm I'm not too sure about that.
No, but it's also ops, I mean, security is always nice to go into for discussions and debates. Um, but in the ops, I know of a use case with uh, DNA center now Catalyst Center, it was running on, uh, I think it was a university and it was giving alerts in analytics that so many clients were trying to connect to the network and it didn't work because they, they stopped authenticating and it was every morning between 7:00 AM and 8:30 AM and after analysis and after a couple of weeks, the DNA sent actually learned that it was normal behavior because the university building was next to the train station where a lot of students were coming in or actually going out and they tried to roam to the educational roaming network. So it was actually normal behavior, which was initially launched as, Hey, this is unexpected behavior.
You have a four wireless network because we have hundreds little bit more of clients trying to log in and then they're out of reach. Yeah, that's logical because the train actually went away and in one of the iterations of DNAC, uh, it was actually improved. And they said, Hey, this is normal behavior.
We stopped reporting on this wireless network issue. Yeah, it's a typical thing in big university network. Sometimes if there are, I will not name here something, but sometimes if there are software update to certain computer games, that looks like a DDoS attack.
Yeah, but it's actually not. It's just a lot of clients want to download the update. But yeah, this is kind of the thing where maybe AI can evolve to the state where they already predict such a thing and connect maybe the dots between an update event and additional traffic or things like that.
Yeah. But not just connect the dots to tell you what's going on, offer fixes for how to prevent it and keep it from happening in the future. And I love the fact that you brought up game updates or, uh, for those of you who are not gamers, um, mobile phone updates, right?
Anytime there is a new version of a mobile operating system or a desktop operating system, especially if it all gets released on the same day and it's not preloaded, um, that is a huge deal for people. In fact, uh, I will tell you that if you are a World of Warcraft fan, you know that they used to preload patches on your machine just so that they didn't have to send like the, the, the big patch on the day that it was released. They could actually just stream out the, the thing to say that it's ready to go.
AI should be able to look at this and go, maybe in the future you need to have, uh, anybody remember the, the Windows updates services servers where you could pre-stage your patches on, on Ws s or uh, maybe hook up to a content delivery network like Akamai, where you can have an iOS update pre-cash locally so that it's not pulling it directly from servers somewhere else. Um, there are ways that the system can extrapolate from the data that it's given to give you ideas. Maybe they're not all implementable, right?
Like, oh yeah, just go spend $50,000 a month with Akamai and all of your bandwidth problems will go away. Yeah, we're not gonna do that, but I wanna see the system start thinking outside the box with the data that it's given, because far too often the solution is, oh, we'll tweak this timer or, uh, you know, we don't know how to fix this and, and that doesn't help me because you've given me the answer I already had and you're supposed to be way smarter than me. So is the data actually paralyzing us?
Because we look at the system and go, you should know how to fix this problem, and if you don't know how to fix it, then I certainly can't figure it out. Maybe more with more data, we have more confidence in this automated action. Of course, uh, there's always the concern that, uh, an automated action is actually bringing down something.
Yeah. So with more data, I think the confidence level will get higher, but still until today, the full automation stream where after detections also a remediation fully automated that is, I think all the vendors haven't 100% figured that out. So that is still something, uh, let's say ahead of us.
Yeah, And I think like, you know what, what's also important, like, you know, it feels to me like what we're discussing here is purely the, the telemetry or the data we're receiving about the network. There's just so much telemetry and data you can receive about the application, about the client experience. So, you know, from from that, from the application monitoring, you can also like get all loads of context.
And I think that's what you were touching on, Dominic, about having loads of different type of data and, and bringing and trying to figure out like what's the context of the, of the data and, you know, different angles, uh, to the data and correlate different data because you know, like one thing is that something is going on in your network. And then the other thing is like user has a bad experience with using like, you know, whatever, if it's like your network, your applications, if it's like somebody who's your client or customer, you know, your network is saying like everything is fine, but the customers are having issues too to access. So, you know, I I think we will see also like much more integration between these type of resources and sources of data.
Um, and I hope, you know, that's, that's where Cisco will probably go much deeper with Splunk. Yeah, and I think in security word in Splunk, this is kind of already, uh, what everybody wants to do. You have these risk levels.
Yeah, you have maybe a lock from the networking, you have an authentication lock, you have a Windows lock, you have all these different data points. One single event is maybe not looking that suspicious, but if you correlate all these together as more data points you have, the higher your confidence level is. But, uh, yeah, uh, the, I think security word is a bit ahead of some other sectors, but I think, uh, similar methodologies you will see all over the place no matter what it is.
So different things will correlate together and then, uh, a certain, let's say level is raised and you have a result that is quite reliable. Yeah, I think, um, that's, uh, application performance. Um, to be honest, networking is really different from applications, but it would be nice to have some sort of service layer in between.
I'm thinking about intent based networking about that, um, where you can actually provide the telemetry data or actually functional data to an AI agent or an agent inside that application that says, Hey, my performance is poor. Could be the network instead of assuming it's always the network, uh, and validates automatically. And then provide the user, Hey, application is slow, but hey, I checked the network for you.
It's not a network, it's probably this or that. And then way the data and the network could improve application performance or explanation application experience. So I guess we come back to the central question, the, the premise here is data causing us to be less efficient or is it enabling us to be more efficient?
And when you answer that question, ask yourself this, is it making us more efficient because of the data itself or because we have interpretation programs allowing us to figure out what the data means. So I'm gonna start, I I I think it's like, it's not data which are in any way are paralyzing us or slowing us down. They are definitely, they can definitely, they have a potential to make us more efficient.
Is that layer on top of the data, uh, how, you know, we, we still lacking off like good tools, uh, to interpret the data right, and correlate the data, right? Uh, I kind of disagree, um, to be honest, if I see so much logging coming at me when I do a troubleshooting on a live firewall or when I'm actually de looking at my logs on my Mac, for example, I get so many events and data that I can actually, I cannot actually see the pattern. So it's kind of paralyzing me too.
So you need those interpretations and that interpretation layer and whether that's Splunk or something else to actually make something of the data. I, I think we, we have to collect the data in any case to make meaningful out of results where the whole industry and everything can improve is how do we have easy access, easy correlatable things. Yeah.
So I think the, the portion from collecting the data, making something out of the data data and then having this easy accessible for you, this is kind of the, the circle we need to, to master. Yeah, I think ultimately it comes down to a question of would you rather have more than you need or be struggling with less than you want? And ultimately, I think that it's better that we have all this data.
Again, it's always been there. We, we just now have visibility into it. But because we know it's there and because we have access to it, what we can do is build tools to help us understand what's going on.
And maybe that means that we don't have to spend hours sifting through syt sys logs to find out what went wrong or where things occurred, and maybe it helps us create trip wires for performance issues or intrusions or things like that. But ultimately, the data is not what is improving the performance of the network or paralyzing us with choice. It's our reaction to the data and how we turn it into information that ultimately makes it more important.
I want to thank each and every one of you for joining us for this episode of the Tech Fill Day podcast. If you want to continue this discussion, please make sure that you subscribe to our YouTube channel so you can leave a comment on this video or subscribe to this in audio form in your favorite podcast application. We don't want you to miss any of our episodes, but we would love it if you'd leave us a rating and a review on one of those episodes so people can understand what we're all about around here.
This podcast was brought to you by Tech Field Day, which is the home for IT practitioners across the enterprise. It is a part of the Futurum group. com slash podcast or make sure you watch one of these episodes on our sister side at Tech Techstrong tv.
Thanks for listening in. We'll be back with more great episodes next week.